PT-2014-5149 · F5 · F5 Big-Iq Cloud/Security

Brandon Perry

·

Publicado

2014-05-05

·

Atualizado

2014-05-23

·

CVE-2014-3220

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions F5 BIG-IQ Cloud and Security versions 4.0.0 through 4.1.0
Description The issue allows remote authenticated users to change the password of arbitrary users. This is achieved by manipulating the name parameter in a request to the "mgmt/shared/authz/users/" API endpoint.
Recommendations For versions 4.0.0 through 4.1.0, consider restricting access to the "mgmt/shared/authz/users/" API endpoint to prevent unauthorized password changes until a fix is available. As a temporary workaround, avoid using the name parameter in requests to this endpoint.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3220

Produtos afetados

F5 Big-Iq Cloud/Security